Skip to content

Products

ServerMask Starting at $199.95

Buy Now Free Trial

ServerMask
Check Your Server Headers:

Stop Information Leakage: Web Server Anonymization

Obscure Headers, Cookies, & Error Messages

divider

Remove Unnecessary HTTP Header & Response Data

Broadcasting your Web server's identity allows intruders to complete their first task -- fingerprinting your technology. ServerMask removes unnecessary HTTP header and response data and camouflages your server by providing false signatures.

Eliminate File Extensions

File extensions like .asp or .aspx are clear indicators that a site is running on a Microsoft server. ServerMask eliminates the need to serve file extensions.

Modify Cookie Values

The ASP session ID cookie, used by the Session object to maintain client state, is a dead giveaway to the type of server you are running. ServerMask can modify your cookie values so that they are generic in nature and non identifiable.

Custom Error Pages

Default messages, pages and scripts of all kinds often contain clues to server identity. ServerMask custom error pages mask that information for better security.

Anti-Reconnaissance

Information masking encourages misguided exploits, snaring attackers with your firewalls and Intrusion Detection System. ServerMask augments these defenses to build more secure networks and return better results on security audits.

Support and Upgrades

space

Port80 Software's ServerMask is clearly the best solution yet produced for managing IIS HTTP headers.

Brett Hill, Microsoft MVP & IIS Guru of www.iistraining.com
Read more testimonials

ServerMask allowed us to surpass our government requirements for host & network anti-reconnaissance... and defeat over 1,300 probe attacks in one audit.

IT Manager & LAN Administrator, U.S. General Services Administration
Read case study

Pricing

Free Trial
Free 30-Day Trial Download

Buy Now
Single Server License
(Unlimited Domains) $199.95

Get Quote
Over Three (3) Servers
Get a quote


Learn more
about Port80 Software evaluation and licensing

What ServerMask Does:

divider

Contributes to PCI Compliance

ServerMask provides application-layer error suppression for PCI compliance.

Per-site Configuration

ServerMask allows for multiple default profiles and the ability to create custom profiles, allowing unique settings to be applied per domain.

Masks Server Name Header

ServerMask will mask the Server name header in a number of ways:

  • Remove altogether
  • Replace with one of 30 other Web server signatures
  • Replace with a custom server name you create
  • Select multiple false Web server signatures and randomize the response (you select how often a response is refreshed).

Rewrite Identifying Session Cookie Names

ServerMask will rewrite identifying session cookie names, such as ASPSessionID and ASP.NET_SessionId, using one or more alternative names and fabricate decoy cookies to further confuse attackers. ServerMask utilizes One-to-many cookie masking.

Rewrite 404 & Application-layer Errors

ServerMask suppresses info leakage by converting 500-range errors to 404 errors, then presenting custom 404 responses.

Remove Identifying File Extensions

ServerMask removes identifying file extensions, such as .asp, .aspx and other Microsoft technologies from source code and URL display.

space

Remove unnecessary HTTP headers

ServerMask removes unnecessary HTTP headers, such as PUBLIC, X-POWERED-BY and others.

Emulate Other Server Data

ServerMask will emulate the ETAG and ALLOW header formats of non-IIS servers. (As well as Apache's HTTP header order.)

Decoys & Error Messages

ServerMask provides Auto-generated decoy cookies and headers, and customizable HTTP error messages.

Diagnostics & Validation

Online diagnostic tool for checking page cacheability and validation tool provided for checking syntax of rule statements

Ease of Use

Completely redesigned user interface, featuring 100% managed code.

System Requirements

  • OS: Windows Server 2003 with Service Pack 2 or Server 2000 with SP4
  • Hardware: x86 (32-bit) or x64 (64-bit)
  • Note: IIS 7 / Windows Server 2008 not yet supported (sign up for the IIS 7 Beta Alert)

The following runtimes are also required but can be installed by the ServerMask installer if not already present on the target system:

Port80 Software stands behind our products 100%. Given the nature of Web server utilities, various environments and third party applications may cause new and unforeseen conflicts. Therefore, Port80 pledges to work with you to ensure our products run in all testing and production environments - if you work with us, we will work with you to make your IIS Web server safer, faster and friendlier.